Description
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never drains, even though the documented behavior redirects all three standard streams. Worker code that writes enough attacker-influenced data to sys.stderr can fill the pipe and block before returning the standard-output protocol response, causing the awaiting process-pool call to remain blocked indefinitely. Applications that run untrusted or faulty worker code capable of producing substantial standard-error output are affected. This issue is fixed in version 4.14.2.
Published: 2026-09-18
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A flaw in the process-pool implementation of AnyIO causes workers to launch child processes with standard error connected to a pipe that the parent never drains, despite documentation stating that all streams are redirected. If a worker writes enough data to sys.stderr—possibly due to malicious or buggy code—the pipe fills, blocking the worker before it can return its normal response. The awaiting coroutine then remains blocked indefinitely, leading to a denial of service. This issue is classified as a resource exhaustion defect (CWE-770) and a race between I/O and process control (CWE-1322).

Affected Systems

All installations of AnyIO prior to version 4.14.2 are susceptible, particularly those that spawn process‑pool workers executing untrusted code. Only the agronholm:anyio product is affected The fix is included in release 4.14.2, so any version older than that must be upgraded.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, implying no confirmed exploits yet. The attack vector requires a process‑pool worker that writes large amounts of data to its standard error stream – this may naturally arise from untrusted or buggy worker code. If such a scenario occurs, the blocking can persist forever, leading to denial of service. The flaw aligns with CWE-770 and CWE-1322. Prompt upgrade mitigates risk entirely.

Generated by OpenCVE AI on September 23, 2026 at 01:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AnyIO to 4.14.2 or later
  • Review and constrain worker code to prevent excessive writes to sys.stderr
  • Apply process‑pool usage policies that limit untrusted code execution

Generated by OpenCVE AI on September 23, 2026 at 01:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5p39-cfhj-2xmp AnyIO process-pool workers can block indefinitely on undrained stderr
History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1322
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Agronholm
Agronholm anyio
Vendors & Products Agronholm
Agronholm anyio

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never drains, even though the documented behavior redirects all three standard streams. Worker code that writes enough attacker-influenced data to sys.stderr can fill the pipe and block before returning the standard-output protocol response, causing the awaiting process-pool call to remain blocked indefinitely. Applications that run untrusted or faulty worker code capable of producing substantial standard-error output are affected. This issue is fixed in version 4.14.2.
Title AnyIO process-pool workers can block indefinitely on undrained stderr
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T18:07:27.772Z

Reserved: 2026-07-20T18:31:39.290Z

Link: CVE-2026-64847

cve-icon Vulnrichment

Updated: 2026-09-18T18:07:23.520Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T18:17:10.930

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-64847

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T17:04:32Z

Links: CVE-2026-64847 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T02:00:10Z

Weaknesses
  • CWE-1322

    Use of Blocking Code in Single-threaded, Non-blocking Context

  • CWE-770

    Allocation of Resources Without Limits or Throttling